How a Compromised Kiln API Cost SwissBorg $41.5 Million in Staked SOL
SwissBorg, the Swiss wealth-management platform, lost 192.6K SOL — roughly $41.5 million — after the staking infrastructure provider it relies on, Kiln, suffered a compromise that gave an attacker withdrawal authority over customer stake accounts. The joint statement from SwissBorg and Kiln frames it as a partner-side API breach; the effect was the same as if the keys had been handed straight to the intruder.
The exploit was not a single smash-and-grab. It was staged eight days in advance and executed in minutes once the groundwork was in place.

01A quiet setup, then a fast drain
On September 8, ZachXBT reported the theft on his Telegram channel before SwissBorg had issued any public statement, writing that "SwissBorg experienced an incident a few hours ago and 192.6K SOL ($41.5M) was stolen on Solana." He pointed directly to the destination wallet.
Attacker's address: TYFWG3hvvxWMs2KXEk8cDuJCsXEyKs65eeqpD9P4mK1
SwissBorg followed roughly fifteen minutes later with its own post, stating that "a partner API (Kiln) was compromised," that the affected SOL Earn Program represented about 193k SOL and under 1% of users, and that "the SwissBorg app remains fully secure."
Kiln subsequently published its own account, describing "unauthorized access to a wallet used for staking operations" and stating that its incident response plan had contained the activity. SwissBorg CEO Cyrus Fazel characterized the source of the breach as "an external DeFi wallet held with a counterparty". Both statements avoided the word "hack," though the on-chain result was unambiguous.
02The eight-day-old transaction that made it possible
The mechanism traces back to an unstaking transaction that occurred eight days before the theft and looked, on its face, routine.
Transaction: 5DCPDEVrnVdM4jHgxYGtuuzvSubg15sSpkBCxexfuApRAfXEmNfokiTyj6bxE52QNGVbPnwm9L3YzcEoMHHEpLV
That transaction deactivated 975.33 SOL (about $200,000) — an ordinary-looking unstaking action of the kind that occurs constantly on Solana. But bundled into the same transaction were eight separate authorization instructions that quietly reassigned withdrawal authority on multiple stake accounts away from SwissBorg's legitimate controllers and over to an address later labeled "SwissBorg Exploiter 1." Blockchain researcher Chaofan Shou drew a direct parallel to the Bybit incident, calling it "Bybit hack V2" — in both cases, attackers concealed a change of control inside a transaction designed to look like normal activity.
03Execution: 192,600 SOL moved in minutes
The dormant authority sat untouched for eight days. Then, at 9:00 AM UTC on September 8, it was used to drain 192,600 SOL in a short window. The funds moved into the wallet Solscan now tags "SwissBorg Exploiter 1":
TYFWG3hvvxWMs2KXEk8cDuJCsXEyKs65eeqpD9P4mK1
From there, the funds were split into two separate paths rather than funneled toward a single exchange.
Path one — the bulk of the funds, left in place: 189,524 SOL (about $40.7 million) moved in a single transfer to a second wallet, where it has remained unmoved since.
Transaction: 5Es6C4oT2SDXaE86P2KUCAJVfdRvfSv8oEMvtJtwsatJcFJ75BxYh4SbjBMEca6voKkc8Pc2Ja1wNE7CHmf3mUx5
Destination holding ~$40.7 million: 2dmoNLgfP1UjqM9ZxtTqWY1YJMHJdXnUkwTrcLhL7Xoq
Path two — a smaller 1,000 SOL, tested through several hops: From the same Exploiter 1 wallet, 1,000 SOL was sent onward through a chain of addresses rather than moved directly to an exchange.
First, Exploiter 1 sent 1,000 SOL to a second controlled address:
Transaction: 2mk89MFQuqnd7dvSyM17QeeDemKmpXeL3hDroBZ6LWrvWMRyYU7RZY4k8tZ55Eg2qAEj2K3qGxBbKYntsHezf2Uk
"SwissBorg Exploiter 2": 6bnSQH4UtGKgo4hUXRj8MeMz2bqPP6hxSaRrBjL96QaT
From there, 100 SOL was forwarded to an intermediate wallet:
Transaction: 32mNq9xgWf8gjWutB8k9KRjYGoxddRRN1pY9FWtk4feRVn5sTnomvFF94i4qMNNbBBzCF8BjmbP1Pe8TCg9qg6zG
Intermediate wallet: 91XrHcYL9eAFB3G7w53X4mXV4zaaZypVe3MrPCyU43dR
That intermediate wallet then sent 99.98 SOL to the Bitget exchange:
Bitget deposit transaction: 26q2ZhRqaj4jq5LtGV1ZgHd5mVc49SSwnxKbUxjuhxBJucor3DA4bJrJjwYz42aWcbaQZ7HD73YBdm77BiJ4jNLf

PeckShield flagged the roughly 100 SOL Bitget deposit, but only after tracing the multi-hop path that preceded it. The pattern — leaving the large sum dormant while cautiously testing smaller amounts through several intermediary wallets before touching a centralized exchange — is consistent with an operator trying to avoid triggering exchange-side detection.
04Response from both companies
SwissBorg CEO Cyrus Fazel stated on X that "the SwissBorg community will not take a loss" and that any shortfall in recovered funds would be covered, effectively committing the company's treasury to make affected users whole. He also stressed that "this was not a breach of the SwissBorg platform ... it was an exploit that occurred on an external DeFi wallet held with a counterparty."
SwissBorg said it had engaged white-hat hackers and security partners to attempt fund recovery, and Fazel thanked blockchain investigators and security firms for assisting in tracing the stolen SOL. The platform paused Solana staking transactions while reiterating that "the SwissBorg app remains fully secure and all other funds in Earn programs are 100% safe."
Kiln, for its part, disabled its dashboard, widget, and APIs while investigating how the unauthorized access occurred.
05What it says about custody through partners
The attackers never touched SwissBorg's own smart contracts or vaults; they compromised Kiln's API layer — the integration connecting SwissBorg's staked funds to the Solana network. The authorization change that ultimately enabled the theft was embedded inside a legitimate-looking unstaking transaction eight days before any funds moved, which is what let it go unnoticed. The word "kiln" refers to a furnace used to permanently harden fired clay — an incidental irony, given that the infrastructure meant to harden SwissBorg's staking security instead became the point of failure.
Roughly $40.7 million of the stolen SOL remains sitting untouched in the second wallet, unmoved since the day of the theft. Only the smaller 1,000 SOL tranche has shown any onward movement, and even that stopped after a roughly 100 SOL test deposit reached Bitget.
The incident illustrates a recurring theme in institutional crypto custody: reassurances about "fully secure" platforms and "institutional-grade" infrastructure depend heavily on the security practices of third-party partners handling withdrawal keys — and a single manipulated transaction, buried among routine operations, was enough to move $41.5 million out of reach.
Get new scam files the moment we publish them — usually 2–3 emails a week.